AK / PERSONAL FILEEDITION 2026.09 / V06DUBAI, UAE

Alex Kelchin — Security Architect & Researcher

== Alex Kelchin ==

Security architecture / Digital assets / AI security

--[ 01 ]

Introduction

I build security systems for fintech, digital assets and AI.

I'm Alex Kelchin, a security architect and researcher based in Dubai. My work spans security leadership, hands-on engineering and vulnerability research.

I follow the whole system: how money moves, who can authorise an action, where a trust boundary sits, and what evidence remains when something goes wrong.

My professional background includes Crypterium, Choise.com and Vault.ist. At Medici AI Lab, my focus is security and AI-security work for regulated digital businesses.

PUBLIC RESEARCH10 credited CVEs across 5 open-source projects A selected, source-linked list. Shared credits are identified.

Professional context

--[ FROM MY WRITING ]

No theory for theory’s sake — only measures that work in the field.

— Alex Kelchin
-- end of file --02 / Experience →
--[ 02 ]

Professional experience

From product security to security ownership.

My work combines architecture, engineering and operational responsibility. Roles across Crypterium, Choise.com and Vault covered a connected product ecosystem; some periods overlap.

Medici AI Lab

CTO / Security & Compliance Advisory

Medici Expert · cybersecurity & AI practice

I develop the cybersecurity and AI-security practice for fintech, Web3 and regulated digital businesses. The work connects technical architecture, security leadership and regulatory readiness with a delivery plan that clients can execute.

My scope includes risk assessments, ISMS design, security policies, architecture reviews and audit evidence. I coordinate certification bodies and penetration-testing providers, define engagement boundaries, and work with leadership, legal, compliance and engineering teams.

I also shape retained vCISO services and AI-assisted assurance workflows: service scope, delivery responsibilities and the evidence clients need for security reviews.

Vault.ist2025 — April 2026

Vault.ist

AI Architect / Head of Security

Digital banking & embedded-finance infrastructure

I led security across a banking-as-a-service platform spanning crypto, cards and custodial operations. My remit covered the transaction path from user or operator intent through ledger checks, approvals, signing and blockchain broadcast.

I designed and operated Fireblocks custody controls: signing policies, co-signer separation, wallet segmentation, recovery and emergency procedures. I worked with engineering on API and webhook integrity, privileged access, cloud security and the secure development lifecycle.

I built detection and response capabilities around SIEM and WAF, coordinated incident investigations and remediation, and led the PCI DSS 4.0 compliance workstream. Related work covered CCSS preparation and control mapping for regulatory-readiness programmes.

Choise.comWithin the group role

Choise.com

Security architecture & engineering

Crypterium / Choise product ecosystem

Choise.com formed part of the same product ecosystem as Crypterium. My work across that environment focused on the security of wallets, card products, APIs and integrations, rather than on an isolated application.

The shared remit included threat modelling, application and infrastructure reviews, secure delivery practices and remediation with product teams. I reviewed transaction controls and on-chain integration risks, including token, sale, staking and administrative flows.

Crypterium2021 — 2025

Crypterium

Head of Security → DevSecOps Lead → Security Architect

Consumer fintech & digital-asset products

I worked across security leadership, DevSecOps and architecture in a multi-product fintech and crypto environment. The progression moved from establishing security ownership and operating processes to designing controls across the product stack.

I helped build the security function, incident-response processes and secure development practices. The technical work spanned cloud and application security, wallet and card infrastructure, code review and vulnerability remediation.

My remit also included bug-bounty coordination, smart-contract security reviews and incident investigations. The focus was to turn findings into engineering changes and operational controls, rather than leave them as reports.

Earlier foundation

Earlier public-sector work involved confidential documentation, controlled access, incident records and internal assurance processes. That background informs how I handle evidence and responsibility in technical systems.

-- end of file --03 / Research →
--[ 03 ]

Security research

Vulnerability research in open-source software.

A selected list of disclosures credited to @Medoedus. Each entry links to a published advisory and its credit source. “Co-reporter” identifies a shared credit, not exclusive discovery or authorship of the fix.

  1. Blind SSRF through OAuth2 avatar synchronisation

    Unvalidated OIDC picture claims can cause a server-side request during avatar synchronisation.

  2. CVE-2026-43905OpenImageIO

    Integer overflow in JPEG 2000 buffer allocation

    An integer overflow in the OpenJPH-backed decoder can produce an undersized allocation.

  3. CVE-2026-43903OpenImageIO

    Heap overflow in SGI RLE decoding

    Run-length bounds that are not enforced in release builds allow out-of-bounds writes.

  4. CVE-2026-42450OpenColorIO

    Stack overflow in the SPI3D LUT parser

    Unbounded parsing of a crafted colour-lookup file can overwrite stack memory.

  5. Integer overflow in ImageChannel::resize

    Incorrect allocation arithmetic can lead to a heap out-of-bounds write.

  6. Path traversal in drive redirection

    An off-by-one validation error permits a final parent-directory component to bypass a path check.

  7. Integer overflow in DWA output-buffer arithmetic

    A missed integer-width conversion can corrupt output-buffer pointer calculations.

  8. Integer overflow in DWA RLE buffer arithmetic

    Incorrect arithmetic in the DWA decoder can lead to heap-memory corruption.

  9. Signed integer overflow in HTJ2K decoding

    Overflow in an HTJ2K decoding calculation affects handling of crafted image data.

  10. Public-only token authorisation bypass

    Organisation API checks did not consistently enforce the public-only token restriction.

Sources: maintainer advisories and CVE records. The list is a selected set of personal credits, checked on 21 September 2026.

Questions I'm working on

Agent authority. How can an AI agent remain useful without inheriting more permission than a task requires?

Security evaluation. How can we make prompt-injection and tool-misuse tests repeatable, with outcomes tied to operational impact?

Evidence. How do we trace an AI-assisted decision through allowed inputs, policy checks and approved actions?

Research interests and ongoing work; separate from the published disclosures above.

-- end of file --04 / Projects →
--[ 04 ]

Side projects & builds

Things I design, build and investigate.

Independent initiatives and internal engineering work, with the context and maturity of each project stated below.

Operanta / Agent Security Platform

Co-founder · architecture & research

A security-and-evidence layer for AI agents operating in regulated workflows. I work on the architecture for explicit permissions, policy enforcement, tool boundaries and an auditable record of agent actions.

The design explores local deployment, capability tracking, signed evidence packs and separation between model output and authorised execution.

KYT & controlled financial workflows

System design · validation tooling

A prototype workstream around transaction-risk signals, controlled decisions and reproducible evidence for financial operations.

My contribution covers the architecture for policy-gated actions, tenant isolation, request integrity and reviewable execution records. Benchmarking and end-to-end validation remain separate from the design claims.

Serebrium / Aegis

Security-platform architecture

A security-operations platform concept bringing together event analysis, asset context and assisted response. The aim is to connect a finding to an accountable action and preserve the evidence behind it.

I designed the platform structure and the interaction between event collection, analysis, reporting and operational workflows. Serebrium Security is also named in the public credit for my OpenEXR disclosure.

Red / Green / Blue security agents

Evaluation design · automation

A set of experimental security-agent workflows for adversarial testing, defensive checks and operational analysis. The work explores how agents can assist an analyst without silently gaining authority over the system under test.

I focus on evaluation criteria, controlled tool use, repeatable test runs and useful evidence. The agents are related experiments within a shared research workstream.

Architecture · access controls

A document-research assistant for legal and compliance work, designed around sensitive material. The architecture combines retrieval with document-level access controls, audit logging and privacy-aware embeddings.

The objective is a useful answer that remains attributable to an allowed source. Internal documents, client identities and implementation details are deliberately excluded from this public description.

Security-operations automation

Workflow design · engineering

Reusable workflows for security reviews, evidence collection, incident documentation and operational reporting. These support the work of a security team rather than replace its responsibility for a decision.

The focus is the connection between findings, ownership, remediation and retained evidence, developed through internal engineering and consulting work.

Third-party tools and repository forks are not listed as original inventions. Client names, private code and sensitive implementation details are omitted.

-- end of file --05 / Education →
--[ 05 ]

Education

A legal foundation for technical security work.

ACADEMIC BACKGROUND

All-Russian State University of Justice

Master’s degree in Law

Moscow, Russia

My legal background informs how I approach regulated environments: responsibility, evidence, the scope of a control and the difference between an assertion and a defensible conclusion.

Professional learning

AI security, investigation and offensive-security training are listed separately under Certificates & training →.

-- end of file --06 / Certificates →
--[ 06 ]

Certifications & training

Credentials, training and continued practice.

Collected from my saved LinkedIn profile and CV. Certification and training tracks are labelled separately. Profile links are not individual certificate-verification links.

Certified AI Security Professional (CAISP)

Practical DevSecOps

LinkedIn profile ↗

Red Team Programme

Group-IB

LinkedIn profile ↗

Cyber Investigator

Group-IB

LinkedIn profile ↗

Offensive Security & Defensive Tracks

TryHackMe

LinkedIn profile ↗

A separate category: corporate assurance

PCI DSS, ISO/IEC 27001 and SOC 2 work belongs to my professional experience. It is not represented here as personal certification. Regulatory-readiness work is described in the Experience file →.

-- end of file --07 / Contact →
--[ 07 ]

Contact

For a useful technical conversation.

Security architecture, digital-asset infrastructure, AI-agent security and research collaboration. For a new engagement, a short description of the system, the decision you need to make and the constraints is a useful starting point.

Email
akelchin96@gmail.com
LinkedIn
linkedin.com/in/alex-kelchin
GitHub
github.com/Medoedus

Dubai, United Arab Emirates. No contact form, analytics or account required. This page does not collect messages.

-- end of file --01 / About →